Administration console

Everything you administer from the Tenant console

Users, invites, roles, MFA reset, branding, email, SSO, devices, sessions and API keys: the LoginMaster Tenant console is the panel from which you govern your users' identity every day. Here is what you actually do, item by item.

Credentials with Argon2id + split-salt · dual-signature RS256 tokens (Tenant + Cloud).

Tenant · Dashboard
LoginMaster Tenant console dashboard with project, user, active-user and device counters and the recent activity feed.
LoginMaster Tenant console · real screenshot with anonymized data.

What you administer from the console

Each console area maps to a real operation the IT team performs on users and projects.

Users, invites and roles

Invite who you need, set enablement or deletion and assign one of the available roles: admin, admin_tenant, manager, user, technician, api_user.

Tenant · Users
Tenant user list with roles, 2FA status, active state and associated projects in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

MFA reset requests

The user opens a request, the admin approves it from the console. TOTP is per project, with an enrolment grace period, deactivation for non-compliance and recovery codes.

Tenant · MFA reset
MFA reset requests section with status filter (pending, approved, rejected) in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

White-label branding and email

Set logo, colors and name — inherited by projects — and customize email templates (LiquidJS + MJML) with it/en i18n and RTL support, per tenant or per project.

Tenant · Branding
Tenant branding settings: company name, logo, primary color and preview, in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

SSO to Google and Entra ID

Configure single sign-on in OAuth 2.0/OpenID Connect to Google Workspace and Microsoft Entra ID (brokering), also per project.

Tenant · SSO
Google Workspace SSO configuration (OAuth 2.0 / OpenID Connect) with Client ID and allowed domains in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

Devices, M2M API keys and IoT

Manage machine identities: user/device pairs, M2M API keys and AWS IoT Core integration via X.509 certificates and the Thing lifecycle.

Tenant · AWS IoT
Project-level AWS IoT integration with Access Key ID, Secret Key and region in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

Sessions and API keys

Revoke sessions with server-side logout and manage API keys: creation, rotation, enablement and disablement for programmatic access.

Tenant · API keys
Project M2M API key management: masked key, status, creation date and rotation in the LoginMaster Tenant console.
Real console screenshot · anonymized data.

Feature matrix

What is available in the console today and what is on the roadmap. No overselling: anything not present is clearly stated as such.

Available
  • Dashboard and project management (keys, per-project SSO config)
  • Users: invite, update, enable/disable, deletion
  • Invites with user-side password setup
  • Roles: admin, admin_tenant, manager, user, technician, api_user
  • MFA recovery via request + admin approval
  • White-label branding (logo, colors, name) inherited by projects
  • LiquidJS + MJML email templates, it/en i18n and RTL
  • Configurable languages and password policy
  • SSO OAuth 2.0/OIDC to Google Workspace and Entra ID (brokering)
  • Devices, M2M API keys and AWS IoT Core (X.509, Thing lifecycle)
  • Session management with server-side revoke/logout
  • API keys: create, rotate, enable/disable
  • Full/Local account deletion (granular GDPR right-to-be-forgotten)
  • Provisioning via REST API + TypeScript/.NET SDKs
  • Application logging
On the roadmap — not yet available
  • SCIM 2.0 (automated provisioning)
  • FIDO2/WebAuthn passkeys
  • Real-time webhooks
  • Native export to SIEM
  • SAML 2.0 federation / generic IdPs

In the meantime, provisioning happens via REST API and TypeScript/.NET SDKs; SSO is OAuth 2.0/OIDC to Google and Entra ID.

Day-2 operations

The recurring tasks an administrator performs from the console once everything is in production.

Invite a user

Send the invite from the Invites section: the user receives the email and sets their password themselves.

Assign a role

Choose among admin, admin_tenant, manager, user, technician and api_user to define what each person can do.

Approve an MFA reset

The user opens an MFA reset request, you approve it from the console: no codes shared over chat.

Customize an email

Edit the templates (LiquidJS + MJML) with it/en i18n and RTL support, per tenant or per project.

Revoke a session

Perform server-side logout and revoke a user's active sessions in case of a lost device.

Rotate an API key

Create, rotate or disable API keys for programmatic access and M2M integrations.

Handle offboarding

Disable or delete the account with Full or Local deletion, for granular GDPR right-to-be-forgotten.

Want to see it in action?

We'll show you the Tenant console with real data: users, roles, MFA reset, branding, SSO and API keys. Book a demo with our team.